Skip to main content
When Controls Work but Fraud Still HappensFraud Detection Analytics
3 min readFor Fraud Risk Managers

When Controls Work but Fraud Still Happens

Fraud teams often find themselves puzzled when incidents occur despite having solid control frameworks. The key question is: what do you do about the risk that remains after implementing controls? Here's what you need to know about assessing and responding to residual risk.

Why Assess Residual Risk?

No control eliminates 100% of risk. Residual risk is what's left after applying a control. For example, transaction velocity limits might not catch a sophisticated attacker who drains an account slowly over time.

Calculate residual risk by multiplying the impact of the fraud risk by the likelihood it'll still occur despite your control. If your account takeover impact is high (4) and the likelihood after controls is moderate (3), your residual risk score is 12. A high score indicates the need to enhance your control or add a compensating one.

Prioritizing Residual Risks

Categorize risks as high, medium, or low. Address high and medium risks immediately, as they're most likely to lead to fraud. Consolidate high-level residual risks for immediate management action. Your risk management team should assess these and prepare a validation report for your Board Risk Management Committee (BRMC). The Chief Risk Officer should report any unattended high risks to the BRMC regularly.

If your card-not-present fraud controls result in a high residual risk score, consider additional layers like device fingerprinting or stricter authentication triggers.

Verifying Decreased Residual Risk

Regular follow-up is essential. Your risk management team should check in with process owners to get feedback on residual risks and control enhancements. Process owners must provide updated assessments on a set schedule.

Track progress by reporting high residual risks and those that have been downgraded. This shows improvement and holds process owners accountable. If a control hasn't reduced residual risk, it may not be configured correctly, monitored, or the fraud typology has evolved.

Inherent vs. Residual Risk

Inherent risk is the exposure before any controls. Residual risk is what's left after controls are in place. Both assessments are needed to understand control effectiveness.

Start with inherent fraud risks. Assess the likelihood and impact, including non-financial impacts like reputational damage. Map existing controls against these risks. The gap between inherent and residual risk shows control effectiveness.

If your inherent risk for payment card skimming is high and your residual risk after implementing Point-to-Point Encryption (P2PE) is low, your control is working. If not, there's a problem.

Building a Fraud Risk Management Program

Residual risk assessment comes after identifying fraud risks, performing inherent risk assessments, and mapping controls. It's crucial for ongoing program effectiveness.

Your framework should include a governance structure with a dedicated anti-fraud entity, a fraud risk assessment methodology, an anti-fraud strategy with specific control activities, and evaluation processes. The anti-fraud entity should manage the residual risk assessment process and ensure high risks are escalated appropriately.

Determining Fraud Risk Tolerance

Define your fraud risk tolerance during strategy development, approved by senior leadership and your board. It's the level of residual risk you're willing to accept after implementing controls, balanced against the cost and operational friction of additional controls.

For some fraud types, your tolerance might be near-zero. For others, you might accept medium residual risk if further control enhancement costs outweigh potential fraud loss. Document your risk tolerance levels and use them to guide resource allocation. If a residual risk exceeds your tolerance, enhance controls or acknowledge that you're operating outside your stated risk appetite, requiring board-level acknowledgment.

Focus Areas Based on Residual Risk Findings

Your anti-fraud strategy should outline activities for preventing, detecting, responding to, monitoring, and evaluating fraud. Use your residual risk profile to determine where to focus efforts.

If residual risk for synthetic identity fraud remains high, consider additional detection layers like link analysis or enhanced verification for first-party fraud indicators. Regularly evaluate existing controls for suitability. A control effective last year might be less so now as fraud schemes evolve. Residual risk scores will indicate when it's time to enhance or replace controls.

Where to Go for More

Maintain documentation of your fraud risk profile, including inherent risks, mapped controls, and residual risk scores. Review the FFIEC IT Examination Handbook for guidance on operational risk management frameworks applicable to fraud risk. Your BRMC needs regular reporting on high residual risks and control enhancement progress to maintain effective oversight.

You Might Also Like